bharatbhasha.net


Free Articles  >>  Email >>  Page 12  >> 

How Private Is Your Email



How Private Is Your Email?   by Richard Lowe


Many years ago I was a consultant for a company who decided they
wanted to perform a security audit of their computer systems. One of the components of
their system that I was requested to check out was email. My client wanted
to determine if their email was secure.

It took me all of a minute to determine that their email was totally and
completely insecure. Fortunately for them, this was in the days before it
was common for company computer systems to be directly connected to the
internet, because their email messages were stored in plain text in a well
known system location. In fact, not only were the email messages stored in a
completely insecure manner, but deleted messages were not actually deleted
until an administrator purged them - and since they didn't have anyone doing
that there was a complete record of company emails going back years in the
past.

I had spent about thirty minutes on this part of the audit so far and was
ready to move on when one of the email messages caught my eye. It was a
particularly juicy romantic message from one employee to another. Well,
romantic is not the right word - highly x-rated would be more like it.

Curious, I continued looking through the emails (off the clock, of course,
since I had already accomplished my mission as regards email) to see what
else was stored in the single message file.

I stayed up all night long, highly amused at what I saw that day. Believe
me, I read some serious blackmail material (if I was that kind of person).
Lots of office romance, some flirting, X-rated messages and other similar
things. I remember one particularly scandalous series of hundreds of emails
going back and forth between one man and a woman (both single) recounting
their relationship for years. Every date, every x-rated encounter was
written up in long, detailed messages. This was very entertaining stuff
indeed.

After a few hours I got bored and stopped reading. I was tempted to keep a
copy of the email data but resisted. That was not part of my mission.
Fortunately, it was also not part of my job to report on indiscretions
committed by various employees. My job was to find and fix any insecurities,
and that's exactly what I did ... I erased the file and set up an automatic
purge to permanently delete old emails. At the time that was the best that I
could do.

I learned a very important lesson that day - email is not private. Not by
any means.

Not much has changed in the intervening years. In fact, email messages are
generally not encrypted in any way. In fact, I have never received an
encrypted email and I've only sent a few in my entire life.

Just so you completely understand, a normal email message is NOT the
equivalent of a letter send through the normal mail. In that case, you write
your note on a piece of paper, put it in an envelope and drop it into the
mail. As far as email is concerned, a better analogy is of a postcard. Your
messages are "written" on the electronic equivalent of postcards.
What does this mean to you? Anyone can look at your message. Quite
literally, anyone.

Let's look at the process to illustrate how and when an email message could
be read by another person.

1) You write the email using your email client. The client may create that
email as a text file in a temporary folder on your hard drive. If someone
looked at your hard drive they could find the email. And it's not any better
if you use a web based email client such as Hotmail. These leave files in
the Temporary Internet Folder, which can easily be recovered. Remember that
the next time you read your emails at work...

2) You do type in the email address to which an email is sent. You could
accidentally type in the wrong address. Worse yet, if you have distribution
or mailing lists, you could accidentally type in one of those, which may
cause an email to inadvertently be sent to the wrong person or people. For
example, if there was a "Joe S Smith" and a "Joe M Smith" at your company
with very close email addresses, you could easily send to the wrong person.

3) The email gets sent to your SMTP server (this is the system which accepts
your email message and forwards along towards the destination). At this
point, the message could, in theory, be read by someone tapping your phone
(or cable) connection. It's not likely (unless you are a spy or something)
but it's possible (and not all that hard).

If you are at work, well, the email probably gets sent to your SMTP server
through something called a proxy server (the computer which manages the
connections to the internet). If so, a copy of the email could be stored on
the proxy server. In theory, this could be examined by someone who had
access to that server.

If you happen to send the email from your companies own email system, it is
highly likely (especially in larger companies) that the email will be
examined by context checking software. This is looking for curse words,
sexual harassment, resumes and any other inappropriate content. Any emails
found which violate company policy may be directly routed to personnel.

4) Okay, the email gets delivered to the SMTP server which it is stored,
still as a simple plain text file, until it is sent to the next SMTP server.
You see, emails never go directly from your outbox to someone's inbox. They
move from server to server until they find their way to their destination.
Each server keeps a copy of the email until it is forwarded to the next one.

5) SMTP servers are computer programs and they can be programmed to do
malicious or unusual things. For example, a law enforcement agency could, in
theory, program an SMTP server to make a copy of any emails directed to a
particular person, and send those copies to their office.

A hacker could, in theory, program an SMTP server (or examine messages
coming across the wire) to look for series of characters that looked like
credit card numbers (they are pretty obvious). These email messages could be
directed to the hacker's own mailbox, thus giving him a steady supply of
income.

6) At any of these SMTP servers, the email could be examined by anyone who
has access to the email system. The internet "wire" could also be "tapped"
and the email message captured on the fly (this is highly unlikely but it is
possible).

7) Since software is simply a series of rules created by human beings, it is
possible for an SMTP server to misunderstand how to route your email. Thus,
a message could be sent to the wrong recipient (this has happened to me a
few times) or to the wrong SMTP server.

8) There is no guarantee that the person who receives a message is actually
the person who is the intended recipient. Someone else could be using their
email client, for example, or an SMTP server may have misdirected the email
to the wrong inbox. In this case it works exactly like the post office - the
mailperson puts the mail in your mail slot, but he does not guarantee that
you will be the one who picks up the mail.

And since most emails are just text, they can be read by whoever happens to
receive them without any problems.

9) Naturally, once an email is receive it is stored on the hard drive of the
recipient. They are usually stored in text files (for normal emails) or in
the Temporary Internet Folder (for web based emails).

10) Of course, once someone does receive an email he or she is free to
forward that email onto just about anyone, starting the whole process over
again.

11) At any point in this entire scenario, the email message can be backed up
or archived. In this case, it can be recovered later and delivered to the
wrong person.

So please, the next time you send those highly personal messages remember
that they can be read by anyone. You have no way to know where these things
wind up or how long they will last. The could pop up anywhere at anytime
with a vengeance.

About Author Richard Lowe :


Richard Lowe Jr. is the webmaster of Internet Tips And Secretsat http://www.internet-tips.net - Visit our website any time to readover 1,000 complete FREE articles about how to improve yourinternet profits, enjoyment and knowledge.


Article Source: http://www.bharatbhasha.net
Article Url: http://www.bharatbhasha.net/email.php/17889

Other Articles by Richard Lowe

Carnivore
by Richard LoweThere have been a number of stories in the press lately about a system called Carnivore (what a great name). This is a hardware/software system designed by the FBI to intercept emails at an ISP so they can be used in a criminal investigation.Before going any further, it may be useful to explain how email works. By it's very nature, email is completely insecure. Any number of people can read that personal note you have written, and it's very possible that your private messages...

Email on the Road
by Richard LoweIf you are anything like me, then you've come to depend on email. In fact, Imust read my email several times a day or I feel very uncomfortable. Thisapplies to both my email from work (which I check a few times after I gethome and on weekends) and my personal email (which I might check once ortwice from the office. Why is it important? Well, email is communication, and I love tocommunicate. I write emails at home to discuss my articles and web site, totalk to family and...

Internet Promotion Email Signatures
by Richard Lowe Perhaps one of the most important methods to promote your web site isincluding some advertising in each and every email you send and allnewsgroup postings that you make. DO NOT spam the newsgroups by sendinguseless messages. Instead, make useful postings which include yoursignature. People will be interested enough to visit your site as long asyou appear to be an intelligent, knowledgeable person.This is generally done by defining an email signature in your email client.It's...

Free Email Accounts
by Richard LoweMost of the people on the planet use the email accounts that come with their internet provider service for their personal email. These are included in the price of the service, so most people just use them because they don't know any better. I'd guess that outside of such services as AOL, WebTV and the like, virtually everyone just uses an email client such as Outlook Express and their ISP's included email accounts.When I began on the internet, I simply used my AOL account to...

Unsubscribing from lists
by Richard LoweI'm sure you've received messages from mailing lists and wanted tounsubscribe. Perhaps you don't remember subscribing in the first place, ormaybe you've just grown tired of the subject. For whatever reason, you justwant to get off the list, and you want off fast.On virtually every list, it is common practice to put the unsubscribeinstructions at the bottom of every message (Yahoo groups, also calledegroups, is an exception in that sometimes there are no unsubscribeinstructions...

Internet Privacy Is This A Joke or What
?   by Richard Lowe How many times have you surfed to a new site, only to be asked for your name, birthday and gender? Did you enter the information that was requested? And if you did enter it, was it the real information or something you made up?I don't know about you, but I find sites which needlessly ask for personal information to be annoying. In fact, I will leave a site the moment a site requires me to enter anything which is not necessary to complete the transaction.Yes, I do understand...

The In s and Out s of Pre Owned Domain Names
by Richard LoweI don't know about you, but sometimes it seems like all of the best domain names have already been taken. On more than one occasion, I've come up with a great domain name for a site, only to find that someone else had already purchased it. I can live with that, but sometimes I've found that it has been purchased by some scum domain scavenger, and that's really annoying.A domain scavenger is someone who purchases a whole bunch of domain names under the theory that people will...

Outlook Express
by Richard LoweOutlook Express is a reasonably nice email, newsgroup and contacts client. One of the best things about this program is the fact that it is free - if, of course, you install Internet Explorer on your system.Let's start with the positive things about this program. The email client is on a par with most other email clients. You can do just about anything that you would ever desire, including creating maintaining email accounts, receiving messages, replying, forwarding, and so on....

Spam Bozo Filters
by Richard LoweA bozo filter is a feature of email and newsgroups clients toallow you to automatically delete messages which you do not wantto receive. This is typically used to eliminate flame spammessages so you don't have to see them.For example, I am subscribed to a number of topics on YahooEgroups. In general these groups have pleasant conversationsamong people who stay on topic and don't flame. There are twoindividuals, however, who are abusive and make no substantialcontributions and...

Black Hole Lists
by Richard LoweWhen you send an email across the internet, you must first loginto your ISP's email system. Generally, you set the logininformation (username and password) in some setup screen, thenquickly forget about it. However, behind the scenes your usernameand password are used to log in each and every time you send email.When the email system receives your message it opens a connectionto the recipient email system and delivers the message. This isthe way email normally works, at least...

Click here to see More Articles by Richard Lowe
Publishers / Webmasters
Tell A Friend
Leave A Comment!
Download this article in PDF
Report Article!
Search through all the articles:


126 Users Online !
Related Articles:
Latest Articles:
 
Email >> Top 50 Articles on Email
Category - >
Advertising Advice Affiliate Programs Automobiles
Be Your Own Mentor Careers Communication Consumers
CopyWriting Crime Domain Names DoT com Entrepreneur Corner
Ebooks Ecommerce Education Email
Entertainment Environment Family Finance And Business
Food & Drink Gardening Health & Fitness Hobbies
Home Business Home Improvement Humour House Holds
Internet And Computers Kiddos and Teens Legal Matters Mail Order
Management Marketing Marriage MetaPhysical
Motivational MultiMedia Multi Level Marketing NewsLetters
Pets Psychology Religion Parenting
Politics Sales Science Search Engine Optimization
Site Promotion Sports Technology Travel
Web Development Web Hosting WeightLoss Women's Corner
Writing Miscellaneous Articles Real Estate Arts And Crafts
Aging


Disclaimer: The information presented and opinions expressed in the articles are those of the authors
and do not necessarily represent the views of bharatbhasha.net and/or its owners.


Copyright © AwareINDIA. All rights reserved || Privacy Policy || Terms Of Use || Author Guidelines || Free Articles
FAQs Link To Us || Submit An Article || Free Downloads|| Contact Us || Site Map  || Advertise with Us ||
Click here for Special webhosting packages for visitors of this website only!
Vastu Shastra

Linux Hosting Provided By AwareIndia